Database/Control plane, storage & DevOps
Jenkins Script Security Plugin: sandbox does not check dynamically added methods, allowing escape
Impact
Sandboxed Groovy scripts can call methods attached to a class at runtime without those calls being checked, so a user allowed only to run sandboxed Pipelines executes code outside the sandbox on the controller. This is a separate defect from the classpath double-download issue in the same advisory round and has its own fix. For a cluster whose Jenkins controller schedules GPU jobs and holds cluster credentials, a sandbox escape turns ordinary pipeline-authoring rights into controller-level code execution. Affects 1415.v9a_f9b_3a_c253d and earlier.
Who can reach it
Any authenticated Jenkins user with permission to define and run sandboxed scripts or Pipelines - the normal privilege level of a developer on a shared controller.
What to do
Update the Script Security Plugin to the version named in the Jenkins advisory and restart the controller. Sandbox rights cannot be relied on as a boundary until the update is in place, so restrict who can author Pipelines on controllers that hold fleet credentials.
References
Related entries
- ntpd (transmit timestamp prediction): A remote attacker who can predict transmit timestamps can crash ntpd or, worseCVE-2020-13817 · ntpd (transmit timestamp prediction)High
- Cisco Nexus 9000 in ACI mode (fabric infrastructure VLAN): A device plugged into a normal front-panel port can talk itsCVE-2021-1228 · Cisco Nexus 9000 in ACI mode (fabric infrastructure VLAN)High
- HTCondor (daemon-to-daemon channel, negotiator/startd/schedd): Secret material crosses the network in the clear whenCVE-2021-45104 · HTCondor (daemon-to-daemon channel, negotiator/startd/schedd)High
- Harbor registry: P2P preheat execution logs readable/updatable by any authenticated user via job ID enumerationCVE-2022-31671 · Harbor registryHigh
- MinIO (admin server-update API): An authenticated request to the server-update admin API traverses out of the intendedCVE-2022-35919 · MinIO (admin server-update API)High
- Cisco Nexus 3000/9000 (health monitoring diagnostics): The health monitoring diagnostics subsystem on Nexus 3000 andCVE-2025-20111 · Cisco Nexus 3000/9000 (health monitoring diagnostics)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.